HTTP Auth

HTTP Auth has one disclosed vulnerability in the WordSec catalog, all reported in 2023; it is fixed as of September 2026. Their average CVSS score is 5.4, and the most serious one scores 5.4 out of 10.

The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).

The one issue recorded for HTTP Auth has a vendor fix available, so running the current release closes it.

All of these findings were reported by Kévin Mosbahi (Mika). HTTP Auth is installed on roughly 6,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.

Strategic Overview

Avg CVSSMedium
5.4/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all HTTP Auth vulnerabilities before they are exploited.

Highest severity on recordCVSS 5.4CVE-2023-27435

HTTP Auth <= 0.3.2 - Cross-Site Request Forgery

Read the full analysis

Vulnerability Records

1 records
Showing 1–1 of 1 reports
HTTP Auth banner
Latestv1.0.1
4.2(6)
84/100
Last Updated
2025-07-22 (1y ago)
Active Installs
6,000+
Downloads
76,201
Requires WP
3.5+
Requires PHP
5.6+
Tested up to
WP 6.8.8
Created
2016-02-18 (11y ago)

This plugin empowers you to set up HTTP Authentication for your website. This adds an extra layer of security by requiring a username and password to access specific areas. Here’s how it benefits you: Enhanced Admin Security: Shield your admin pages from brute-force attacks by adding a login barrier. Controlled Crawling: Restrict crawlers from accessing your site during development, preventing unnecessary indexing. Post-Launch Access Control: Maintain control over admin page access even after your website goes live. Easy Activation/Deactivation: Conveniently enable or disable HTTP Auth without deactivating the plugin entirely. Help Us Improve! I am constantly working to enhance this plugin and your feedback is valuable. If you are happy with the plugin, consider leaving a review on WordPress.org. Your positive feedback motivates us to keep improving! Link to Reviews: https://wordpress.org/support/plugin/http-auth/reviews/?rate=5#new-post Bug Reports We welcome bug reports for HTTP Auth on GitHub: https://github.com/samiahmedsiddiqui/http-auth. Please remember that GitHub is primarily for bug reporting, and issues not classified as genuine bugs may be closed. From within WordPress Visit &#8216;Plugins > Add New’ Search for HTTP Auth Activate HTTP Auth from your Plugins page. Go to “after activation” below. Manually Upload the http-auth folder to the /wp-content/plugins/ directory Activate HTTP Auth through the &#8216;Plugins’ menu in WordPress Go to “after activation” below. After activation Go to the plugin settings page and set up the plugin for your site. You’re done!

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C